Tuesday, 18 August 2026

The impact of ransomware attacks on hospitals and patients

In May 2021, the Waikato District Health Board (DHB) was hit with a ransomware attack. It took some four weeks for clinical services to be restored, and in the meantime, surgeries were postponed, and patients and health staff were negatively impacted. Health services have been a common target of these ransomware attacks, and the consequences could be tragic. Fortunately, in the case of the Waikato DHB attack, there is no evidence of patients dying as a result.

That isn't always the case though. This recent article by Hannah Neprash, Claire McGlave, and Sayeh Nikpay (all University of Minnesota), published in the American Economic Journal: Economic Policy (ungated earlier version here) looks at the impact of ransomware attacks on hospitals in the US. They use Medicare administrative claims data, along with data from HackNotice and the Office for Civil Rights Breach Portal on ransomware attacks on hospitals. They find 74 attacks over the period from 2016 to 2021, affecting 160 hospitals.

Neprash et al. then look at the effect of the ransomware attack on hospital volume (separating emergency room, inpatient, and outpatient volume), and hospital revenue from Medicare, as well as patient mortality. They use a difference-in-differences analysis, which involves looking at the difference in each outcome variable between the time before and the time after the ransomware attack, for hospitals that were attacked, and those that were not. They identify control group hospitals (that weren't attacked) as those most similar to the affected hospitals in terms of non-profit status, health system membership, and quartile of Medicare admissions in the year prior to the attack. They also conduct an event study, which allows them to look at how the impact changes over time.

In their main analysis, Neprash et al. find that:

During the initial week of a ransomware attack, hospital volume falls by 17–24 percent in the ER, inpatient, and outpatient settings. Medicare revenue declines by 19–39 percent at ransomware-attacked hospitals. A full recovery to pre-attack volume and revenue occurs within two to three weeks on average. A back-of-the-envelope calculation suggests that the average ransomware attack reduces annual hospital revenue by roughly 1 percent.

These are quite substantial effects (and notice the recovery time is not dissimilar to the case of the Waikato DHB attack). What happens to the patients who are affected by their hospital being attacked? It turns out that many patients were redirected to nearby hospitals, although the extent of redirection differs by type of care, as when Neprash et al. look at the local hospital market rather than the individual hospital, they find that:

...nearby hospitals absorb displaced emergency department patient volume from attacked facilities, such that market-level emergency department volume does not change during attacks. Inpatient and outpatient hospital volume is partially absorbed by nearby hospitals, though not fully, resulting in a market-level volume decrease during the first week of a ransomware attack.

That also means the costs of a ransomware attack spill over to neighbouring hospitals, which have to absorb some of the displaced patients. What about patient outcomes? Here are the most serious impacts, as Neprash et al. find that:

...ransomware attacks increase in-hospital mortality for patients already admitted to ransomware-attacked hospitals when the attack begins, compared to patients whose admissions concluded in the five weeks prior. Our estimates suggest that ransomware attacks resulted in the deaths of between 69 and 76 Medicare patients—representing roughly 1 Medicare death per month due to ransomware over the course of our study period.

Notice the effects fall on patients who were already in hospital care at the time the attack started. Many of those patients may not be easily redirected to other hospitals, and so have little choice but to ‘ride out’ the attack in the affected hospital. Neprash et al. also find larger mortality impacts at smaller or independent hospitals, during particularly severe attacks, and among patients with complex care needs (such as patients in intensive care, or those with multiple chronic conditions). Neprash et al. don't offer much of a policy prescription in their discussion of their results, limiting themselves to recommending:

...a combination of policies designed to reduce the likelihood of any successful ransomware attacks (e.g., minimum cybersecurity standards for hospitals) and policies designed to reduce the severity of ransomware attacks when they do happen (e.g., incident planning requirements).

For me, the key takeaway from this research is that ransomware attacks are not just a cybersecurity issue, they are a health security issue. We can be thankful that the Waikato DHB attack avoided the much worse outcomes that US hospitals have experienced. The response nevertheless required serious efforts by IT professionals and imposed a heavy workload on health and administrative staff. We should treat these results as a warning that hospitals need to treat resilience to cyberattacks as part of their core patient-safety planning, rather than simply as an IT problem.

No comments:

Post a Comment